CVE-2025-14183

MEDIUM

SGAI Space1 NAS N1211DS <1.0.915 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was found in SGAI Space1 NAS N1211DS up to 1.0.915. This issue affects the function GET_FACTORY_INFO/GET_USER_INFO of the file /cgi-bin/JSONAPI of the component gsaiagent. The manipulation results in unprotected storage of credentials. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (6)

Core 6
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.334603
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.334603
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.698566
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.698567

Scores

CVSS v3 4.3
EPSS 0.0023
EPSS Percentile 13.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-255 CWE-256
Status published
Products (1)
SGAI/Space1 NAS N1211DS 1.0.915
Published Dec 07, 2025
Tracked Since Feb 18, 2026